Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Gitlab

Gitlabвеб-платформа для управления проектами и репозиториями программного кода, работа которой основана на популярной системе контроля версий Git.

Релизный цикл, информация об уязвимостях

Продукт: Gitlab
Вендор: gitlab

График релизов

19.019.119.220262027

Релизные элементы

KBВерсияБилдДата доступности
17.0.817.0.8
17.0.717.0.7
17.0.617.0.6
17.0.517.0.5
17.0.417.0.4
17.0.317.0.3
17.0.217.0.2
17.0.117.0.1
17.0.017.0.0

Показывать по

Недавние уязвимости Gitlab

Количество 5 943

github логотип

GHSA-jc72-5mcm-wv54

около 4 лет назад

GitLab through 12.9 is affected by a potential DoS in repository archive download.

EPSS: Низкий
github логотип

GHSA-xhg3-wf98-646c

около 4 лет назад

GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.

EPSS: Низкий
github логотип

GHSA-4hq6-hm84-9r6r

около 4 лет назад

GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-mxch-5ff5-jp4w

около 4 лет назад

GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.

EPSS: Низкий
github логотип

GHSA-q5jf-8f55-j92v

около 4 лет назад

GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.

EPSS: Низкий
github логотип

GHSA-fjgv-pw7x-g797

около 4 лет назад

GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.

EPSS: Низкий
github логотип

GHSA-6q57-rfmx-mxr3

около 4 лет назад

GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,

EPSS: Низкий
github логотип

GHSA-5qpg-r237-3pm4

около 4 лет назад

GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.

EPSS: Низкий
github логотип

GHSA-785p-hcfx-v324

около 4 лет назад

GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.

EPSS: Низкий
github логотип

GHSA-4mm8-64px-38hf

около 4 лет назад

GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-jc72-5mcm-wv54

GitLab through 12.9 is affected by a potential DoS in repository archive download.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xhg3-wf98-646c

GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.

1%
Низкий
около 4 лет назад
github логотип
GHSA-4hq6-hm84-9r6r

GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-mxch-5ff5-jp4w

GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.

1%
Низкий
около 4 лет назад
github логотип
GHSA-q5jf-8f55-j92v

GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.

1%
Низкий
около 4 лет назад
github логотип
GHSA-fjgv-pw7x-g797

GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.

1%
Низкий
около 4 лет назад
github логотип
GHSA-6q57-rfmx-mxr3

GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,

1%
Низкий
около 4 лет назад
github логотип
GHSA-5qpg-r237-3pm4

GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.

1%
Низкий
около 4 лет назад
github логотип
GHSA-785p-hcfx-v324

GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.

1%
Низкий
около 4 лет назад
github логотип
GHSA-4mm8-64px-38hf

GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться